cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 92 of 107
CVE-2021-37996P4MEDIUMCVSS 5.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37996 [MEDIUM] CVE-2021-37996: chromium - Insufficient validation of untrusted input Downloads in Google Chrome prior to 9... Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.469
debian
CVE-2025-12439P4MEDIUMCVSS 5.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12439 [MEDIUM] CVE-2025-12439: chromium - Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows... Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0
debian
CVE-2020-6441P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6441 [MEDIUM] CVE-2020-6441: chromium - Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.9... Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 81.0.4044.92-1) bullseye: resolved (fixed in 81.0.4044.92-1) forky: resolved (fixed in 81.0.4044.92-1) sid: resolved (fixed in 81.0.4044.92-1) trixie: resolved (fixed in
debian
CVE-2024-6995P4MEDIUMCVSS 4.7fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6995 [MEDIUM] CVE-2024-6995: chromium - Inappropriate implementation in Fullscreen in Google Chrome on Android prior to ... Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open f
debian
CVE-2025-12433P4MEDIUMCVSS 4.3fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12433 [MEDIUM] CVE-2025-12433: chromium - Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allow... Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1)
debian
CVE-2020-15989P4MEDIUMCVSS 5.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15989 [MEDIUM] CVE-2020-15989: chromium - Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a re... Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.428
debian
CVE-2018-18358P4MEDIUMCVSS 5.7fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18358 [MEDIUM] CVE-2018-18358: chromium - Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0... Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 7
debian
CVE-2021-37990P4MEDIUMCVSS 5.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37990 [MEDIUM] CVE-2021-37990: chromium - Inappropriate implementation in WebView in Google Chrome on Android prior to 95.... Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) tri
debian
CVE-2024-3838P4MEDIUMCVSS 5.5fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3838 [MEDIUM] CVE-2024-3838: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60... Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved
debian
CVE-2018-20073P4LOWCVSS 5.5fixed in chromium 72.0.3626.81-1 (bookworm)2018
CVE-2018-20073 [MEDIUM] CVE-2018-20073: chromium - Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 a... Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: resolved (fixed in 72.0.36
debian
CVE-2019-5779P4MEDIUMCVSS 4.3fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5779 [MEDIUM] CVE-2019-5779: chromium - Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3... Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: re
debian
CVE-2020-6437P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6437 [MEDIUM] CVE-2020-6437: chromium - Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 a... Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application. Scope: local bookworm: resolved (fixed in 81.0.4044.92-1) bullseye: resolved (fixed in 81.0.4044.92-1) forky: resolved (fixed in 81.0.4044.92-1) sid: resolved (fixed in 81.0.4044.92-1) trixie: resolved (fixed in 81
debian
CVE-2020-6527P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6527 [MEDIUM] CVE-2020-6527: chromium - Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 al... Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: res
debian
CVE-2021-30589P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30589 [MEDIUM] CVE-2021-30589: chromium - Insufficient validation of untrusted input in Sharing in Google Chrome prior to ... Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.457
debian
CVE-2019-5839P4MEDIUMCVSS 4.3fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5839 [MEDIUM] CVE-2019-5839: chromium - Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 a... Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.
debian
CVE-2023-7013P4MEDIUMCVSS 4.7fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-7013 [MEDIUM] CVE-2023-7013: chromium - Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045... Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.1
debian
CVE-2025-13992P4MEDIUMCVSS 4.7fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-13992 [MEDIUM] CVE-2025-13992: chromium - Side-channel information leakage in Navigation and Loading in Google Chrome prio... Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.66-1) sid: resolved (fixed in 139.
debian
CVE-2024-7005P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7005 [MEDIUM] CVE-2024-7005: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome pri... Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: re
debian
CVE-2024-7004P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7004 [MEDIUM] CVE-2024-7004: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome pri... Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: re
debian
CVE-2019-5765P4MEDIUMCVSS 5.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5765 [MEDIUM] CVE-2019-5765: chromium - An exposed debugging endpoint in the browser in Google Chrome on Android prior t... An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (f
debian
Debian Chromium vulnerabilities | cvebase